<?xml version="1.0" encoding="UTF-8"?> 
<?xml-stylesheet href="https://dev.horde.org/themes/horde//default/feed-rss.xsl" type="text/xsl"?> 
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"> 
 <channel> 
  <title>HTML messages created with IMP and FCKEDIT have formatting stripped while viewing with IE6/7 </title> 
  <pubDate>Fri, 10 Apr 2026 04:00:02 +0000</pubDate> 
  <link>https://bugs.horde.org/ticket/6891</link> 
  <atom:link rel="self" type="application/rss+xml" title="HTML messages created with IMP and FCKEDIT have formatting stripped while viewing with IE6/7 " href="https://bugs.horde.org/ticket/6891/rss" /> 
  <description>HTML messages created with IMP and FCKEDIT have formatting stripped while viewing with IE6/7 </description> 
 
   
   
  <item> 
   <title>If you receive an HTML formatted message created in IMP..  w</title> 
   <description>If you receive an HTML formatted message created in IMP..  when you view it in IE6/7, IMP will strip some of the formatting in the name of protecting us from XSS...



&lt;h1&gt;&lt;span XSSCleaned=&quot;color: rgb(255, 0, 0);&quot;&gt;&lt;strong&gt;

&lt;span XSSCleaned=&quot;font-size: xx-large;&quot;&gt;

&lt;span XSSCleaned=&quot;font-family: Verdana;&quot;&gt;Red&lt;br /&gt;

&lt;/span&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/h1&gt;



You can view the message properly using the same IMP installation and other browsers / platforms.   The problem mostly seems to be with &quot;spans&quot; and &quot;styles&quot;.  I&#039;ve also seen it strip formatting from Mail.app messages.</description> 
   <pubDate>Tue, 10 Jun 2008 19:16:08 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/6891#t46210</link> 
  </item> 
   
  <item> 
   <title>What&#039;s the bug/action here though? IE allows javascript in i</title> 
   <description>What&#039;s the bug/action here though? IE allows javascript in inline styles (expression: ...), so we have to strip them.</description> 
   <pubDate>Tue, 10 Jun 2008 19:26:01 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/6891#t46212</link> 
  </item> 
   
  <item> 
   <title>Ah. 



Is this documented someplace?  (e.g. &quot;When using IE,</title> 
   <description>Ah. 



Is this documented someplace?  (e.g. &quot;When using IE, we strip some formating because IE allows JS to be embedded in style information...&quot;)



Mostly, I think our help desk was expecting the same messages to be displayed the same across browsers.. and I was surprised that IMP + IE was filtering some stuff in the name of XSS protection, when it wasn&#039;t on other browsers.</description> 
   <pubDate>Tue, 10 Jun 2008 19:45:18 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/6891#t46214</link> 
  </item> 
   
  <item> 
   <title>&gt; Is this documented someplace?  (e.g. &quot;When using IE, we st</title> 
   <description>&gt; Is this documented someplace?  (e.g. &quot;When using IE, we strip some 

&gt; formating because IE allows JS to be embedded in style 

&gt; information...&quot;)



Probably not anywhere user-visible. Suggestions on where that might usefully go would be welcome.</description> 
   <pubDate>Thu, 12 Jun 2008 18:32:07 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/6891#t46342</link> 
  </item> 
   
  <item> 
   <title>Not closing out the possibility of doc improvements, but we </title> 
   <description>Not closing out the possibility of doc improvements, but we can either reopen this, or you can post them elsewhere.</description> 
   <pubDate>Mon, 30 Jun 2008 18:55:59 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/6891#t47027</link> 
  </item> 
   
   
 
 </channel> 
</rss> 
